Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

System.Security.Cryptography.Pkcs dependency has severe vulnerability #1236

Closed
mganss opened this issue Dec 12, 2023 · 7 comments
Closed

System.Security.Cryptography.Pkcs dependency has severe vulnerability #1236

mganss opened this issue Dec 12, 2023 · 7 comments
Labels

Comments

@mganss
Copy link

mganss commented Dec 12, 2023

System.Security.Cryptography.Pkcs which is an indirect dependency via System.Security.Cryptography.Xml has a vulnerability. Please update the NuGet package. More details at mganss/ExcelMapper#288.

@mganss mganss added the bug label Dec 12, 2023
@tonyqus
Copy link
Member

tonyqus commented Dec 12, 2023

I have merged #1183 just now.

@tonyqus
Copy link
Member

tonyqus commented Dec 12, 2023

Btw, I see your download number is lower than NPOI.mapper? Do you know any reason?

I did compared these 2 libraries and I see your updates are more frequent and solid than NPOI.mapper. But it's weird that there is no effect on increasing the download number.

image

@mganss mganss closed this as completed Dec 13, 2023
@mganss
Copy link
Author

mganss commented Dec 13, 2023

@tonyqus I have no idea. On top of that, Npoi.Mapper seems to be heavily inspired by ExcelMapper (started about a year later, some identical class and property names etc). I'll expand the description of the NuGet package, perhaps that'll help.

@tonyqus
Copy link
Member

tonyqus commented Dec 13, 2023

Perhaps you can write a post about ExcelMapper on medium.com. Then I help promote this post to the community

@tonyqus
Copy link
Member

tonyqus commented Dec 18, 2023

I notice that the download number gap between NPOI.Mapper and ExcelMapper is somewhat expanding in the last 6 month.
image

@mganss
Copy link
Author

mganss commented Dec 20, 2023

It's strange as ExcelMapper has more stars, more users. and more interaction in general on GitHub. NuGet downloads for Npoi.Mapper have been higher from the beginning. Perhaps the NPOI prefix in the package name draws people?

@mganss
Copy link
Author

mganss commented Dec 20, 2023

Also I think the linear scale on nugettrends is misleading. Currently, Npoi.Mapper has about 4/3 downloads but the ratio was higher in the past. If you set the scale to 6 years you can see that Npoi.Mapper had about 5000 downloads on December 17, 2017, when ExcelMapper had about 800.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants